Privacy Policy
Effective August 16, 2026
1. What we collect
- Account information. Your name, email address and profile image, managed by our authentication provider (Clerk). We mirror this into our own database to run your workspace.
- Workspace data. The projects you create, the members you invite (their email addresses and roles), plan and subscription status, and an append-only audit log of actions taken in your workspace — by people and by agents.
- Connected-site data. Content the platform reads from the public pages of websites you connect, and — if you connect Google Search Console — the metrics Google reports for your site. OAuth refresh tokens are encrypted at rest (AES-256-GCM) and are never shown back to anyone, including you.
- Visitor measurement on your sites. If you use campaign tracking, our endpoint records events such as visits and conversions tied to a campaign code. It is built to refuse personal data: events carry no names, no email addresses, and requests are only accepted from domains you have authorised.
2. What we deliberately do not hold
- Payment details. Subscriptions are processed by PayPal. Card and bank details never touch our systems; we store only the subscription's identifier and status.
- Passwords. Authentication is handled by Clerk; we never see or store your password.
- Credentials to your platforms. Automated delivery works by signed webhooks to endpoints you control. We do not ask for or store your CMS, social or repository passwords.
3. How we use data
To operate the service: researching demand for your sites, drafting and scoring content, enforcing your plan's limits, attributing results, and keeping the audit record that lets you see what the agents did and why. Site content is processed by third-party AI providers (such as Google and OpenRouter) to generate analysis and drafts; we send them the content needed for the task, not your account data. We do not sell personal data or use your data to advertise to you.
4. Cookies
The product site and console use only the cookies required for authentication and security, set by Clerk. There are no advertising or cross-site tracking cookies.
5. Where data lives and who processes it
Data is stored with our infrastructure providers: Neon (PostgreSQL database), Vercel (hosting), Clerk (authentication) and PayPal (billing), with AI processing by the providers named above. Each processes data only to provide their part of the service.
6. Retention and deletion
Workspace data is kept while your account is active. Deleting a project removes its research, drafts and schedule; deleting your account removes your workspace and its data, subject to records we must keep (such as billing history required for accounting). To request deletion or a copy of your data, contact us at the address below.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Write to us and we will honour them. If you are in the EU/EEA or UK, you also have the right to complain to your data-protection authority.
8. Changes
If this policy changes materially, we will announce it in the console or by email before the change takes effect.
9. Contact
Privacy questions and requests: support@collectcustomers.com.